How to remove vAutoKMS.exe
- File Details
- Overview
- Analysis
vAutoKMS.exe
The module vAutoKMS.exe has been detected as Trojan.Agent
File Details
| Product Name: |
|
| MD5: |
0ed398a4d031b9cfb10e3fedf97ad836 |
| Size: |
600 KB |
| First Published: |
2017-05-21 06:06:30 (8 years ago) |
| Latest Published: |
2024-02-24 23:48:09 (2 years ago) |
| Status: |
Trojan.Agent (on last analysis) |
|
| Analysis Date: |
2024-02-24 23:48:09 (2 years ago) |
| %sysdrive%\windows |
| %sysdrive%\windows.old\windows |
| %windir% |
| %sysdrive%\$windows.~bt\newos |
| %sysdrive%\windows.old |
| %sysdrive%\windows.old.000 |
| %sysdrive%\4.các dữ liệu cũ |
| %sysdrive%\backup 23-10-18 |
| %sysdrive%\4.các dữ liệu cũ\du lieu tan |
| %windir% |
| AutoKMS.exe |
| vAutoKMS.exe |
| gAutoKMS.exe |
| AutoKMS_file crack MSoffice.exe |
|
63.1% |
|
|
15.5% |
|
|
2.2% |
|
|
1.9% |
|
|
1.8% |
|
|
1.5% |
|
|
1.4% |
|
|
1.1% |
|
|
0.9% |
|
|
0.9% |
|
|
0.7% |
|
|
0.7% |
|
|
0.5% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.4% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.3% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.2% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
|
0.1% |
|
| Windows 7 |
81.2% |
|
| Windows 10 |
13.1% |
|
| Windows 8.1 |
3.0% |
|
| Windows 8 |
1.1% |
|
| Windows XP |
0.9% |
|
| Windows Vista |
0.3% |
|
| Windows Embedded Standard |
0.3% |
|
| Windows Server 2008 R2 |
0.1% |
|
Analysis
| Subsystem: |
Windows GUI |
| PE Type: |
pe |
| OS Bitness: |
32 |
| Image Base: |
0x00400000 |
| Entry Address: |
0x0003c69e |
| MVID: |
f251ddb3-e6eb-4727-95d8-f636ef4ddd2f |
| Typelib ID: |
58acc958-754c-480c-9c3b-77a6573ae75e |
| Name |
Size of data |
MD5 |
| .text |
239616 |
bd84d52ad14176b585b99452926b279d |
| .rsrc |
373760 |
dc395030dd388ca4ff31ab2fadd82b98 |
| .reloc |
512 |
f5d7807b89c74fc390e8300801405440 |